Christopher Davis is CEO of cybersecurity firm HYAS InfoSec in Nanaimo.

Christopher Davis is CEO of cybersecurity firm HYAS InfoSec in Nanaimo.

Nanaimo cybersecurity expert helps evaluate campaign e-mail server

NANAIMO - Christopher Davis, CEO of HYAS InfoSec, called to consult on Trump-Russia computer links.

A Nanaimo cybersecurity expert was recently called upon to help shed light on cryptic information gleaned from a computer scientist about communications between the Trump presidential campaign and a Russian bank.

The computer scientist, who goes by the alias Tea Leaves, is one of just a few people worldwide entrusted with a list of nearly all the web servers in the world who hunt malware, programming such as viruses and other hostile software that can damage networks, disrupt communication and control systems, steal information or commit other malicious acts. Their work helps protect private users, businesses, governments, anyone connected to the Internet.

To communicate, the Internet uses a set of protocols called the Domain Name System or DNS – similar to  street address or phone numbers – to ensure information is passed between its intended senders and recipients. In late July, some DNS data caught Tea Leaves’ eye that has led to reports in the news media suggesting an e-mail server owned by U.S. presidential candidate Donald Trump was in communication with Russia.

“What we’re seeing here is that Alpha Bank in Russia is doing lots and lots of these phonebook lookups for this [e-mail] server connected to the Trump organization,” said Christopher Davis, founder and CEO of Nanaimo-based cybersecurity firm HYAS InfoSec, who was called upon to consult on the data.

Davis received the U.S. Federal Bureau of Investigation’s Director’s Award in 2013 for bringing down an international network of more than 15 million computers, hijacked by malware to steal passwords, credit card numbers and personal data in 2009. His work helped prosecute a Slovenian and two Spaniards behind the scheme.

The Trump e-mail server appeared to be set up for mass marketing the Trump Card Privileges Program, but based on the data Davis looked at, the e-mail server appeared to be talking to only two places, an Alpha Bank server in Russia and another at U.S.-based Spectrum Health.

“If I’m setting up a marketing mail server, what kind of [poor] marketing am I doing if I’m only sending out marketing messages to two places?” Davis said. “Those are the questions I have and there’s no good answer for them. I don’t know what the answer is.”

Unfortunately, reading DNS data doesn’t reveal communication content. What it does reveal are patterns that can indicate whether communications are being sent automatically by malware or by people typing at keyboards. Davis thinks it’s the latter, but said he can’t draw any conclusions about who they are or what’s being communicated.

“There was like five of us that sort of went over this with a fine-tooth comb and looked at it pretty deeply. There’s a bunch of weirdness to it that doesn’t match anything in my 20 years, 25 years of doing IT that I’ve ever seen before,” Davis said. “It’s just that I’ve never seen anyone set up to send spam to two people. It’s kind of a ridiculous thing to do.”

Just Posted

Regional District of Nanaimo is seeking input from the public for its transit redevelopment strategy. (News Bulletin file)
Public input sought as RDN works on transit redevelopment strategy

RDN wants to know where people want bus stops, shelters and pedestrian and cycling connections

Douglas Holmes, current Alberni-Clayoquot Regional District chief administrative officer, is set to take on that position at the Regional District of Nanaimo come late August. (Submitted photo)
Regional District of Nanaimo’s next CAO keen to work on building partnerships

Douglas Holmes to take over top administrator role with RDN this summer

(PQB News file photo)
Fireworks report highlights enforcement challenges for Regional District of Nanaimo

Director: ‘I just think it’s wasting everybody’s time’

Neighbours fight a small late-night bush fire with garden hoses and shovels in Cinnabar Valley on June 5. They couldn’t get help from local fire services because the fire was located in an area under B.C. Wildfire Services jurisdiction. (Photo courtesy Muriel Wells)
Nanaimo residents on edge of city limits left to put out bush fire themselves

Cinnabar Valley residents tackle fire with hoses and buckets for two and a half hours

Nanaimo artist Dave Stevens is displaying paintings inspired by arbutus trees and the Millstone River at Nanaimo Harbourfront Library from now until the end of fall. (Josef Jacobson/News Bulletin)
Nanaimo writer and artist’s work goes up at Harbourfront library

Dave Stevens presents work inspired by arbutus trees and the Millstone River

Members of the Department of Fisheries and Oceans’ Marine Mammal Response Program rescued an adult humpback what that was entangled in commercial fishing gear in the waters off of Entrance Island on Thursday, June 10. (Photo courtesy Marine Mammal Response Program)
Rescuers free humpback ‘anchored’ down by prawn traps near Nanaimo

Department of Fisheries and Oceans responders spend hours untangling whale

Two-year-old Ivy McLeod laughs while playing with Lucky the puppy outside their Chilliwack home on Thursday, June 10, 2021. (Jenna Hauck/ Chilliwack Progress)
VIDEO: B.C. family finds ‘perfect’ puppy with limb difference for 2-year-old Ivy

Ivy has special bond with Lucky the puppy who was also born with limb difference

A million-dollar ticket was sold to an individual in Vernon from the Lotto Max draw Friday, June 11, 2021. (Photo courtesy of BCLC)
Lottery ticket worth $1 million sold in Vernon

One lucky individual holds one of 20 tickets worth $1 million from Friday’s Lotto Max draw

“65 years, I’ve carried the stories in my mind and live it every day,” says Jack Kruger. (Athena Bonneau)
‘Maybe this time they will listen’: Survivor shares stories from B.C. residential school

Jack Kruger, living in Syilx territory, wasn’t surprised by news of 215 children’s remains found on the grounds of the former Kamloops Indian Residential School

A logging truck carries its load down the Elaho Valley near in Squamish, B.C. in this file photo. THE CANADIAN PRESS/Chuck Stoody
Squamish Nation calls for old-growth logging moratorium in its territory

The nation says 44% of old-growth forests in its 6,900-square kilometre territory are protected while the rest remain at risk

Flowers and cards are left at a makeshift memorial at a monument outside the former Kamloops Indian Residential School to honour the 215 children whose remains are believed to have been discovered buried near the city in Kamloops, B.C., on Monday, May 31, 2021. THE CANADIAN PRESS/Darryl Dyck
‘Pick a Sunday:’ Indigenous leaders ask Catholics to stay home, push for apology

Indigenous leaders are calling on Catholics to stand in solidarity with residential school survivors by not attending church services

“They will never be forgotten, every child matters,” says Sioux Valley Chief Jennifer Bone in a video statement June 1. (Screen grab)
104 ‘potential graves’ detected at site of former residential school in Manitoba

Sioux Valley Dakota Nation working to identify, repatriate students buried near former Brandon residential school

The Queen Victoria statue at the B.C. legislature was splattered with what looks like red paint on Friday. (Nicole Crescenzi/News Staff)
Queen Victoria statue at B.C. legislature vandalized Friday

Statue splattered with red paint by old growth forest proponents

Most Read